RSAC 2025 Recap: SOAR

While attending RSAC 2025, our team explored next-gen SOAR platforms.

What You Missed on the Expo Floor

Big SOAR Moments at RSA 2025:

  • Splunk unveiled a next-gen SOAR engine built on LLM-driven automation
  • Swimlane introduced Low-Code Autonomous Triage Agents
  • Tines demoed no-code SOAR use cases for business ops + insider threat
  • Open Text released Titanium X for faster decision-making
  • Anomali introduced its integrated agentic AI technology

At RSAC 2025, SOAR platforms weren’t just automating workflows—they were making decisions. We joined sessions like “Unleashing Generative AI for Automated Excellence” and “From Alert Fatigue to Actionable Response,” where SOC leaders and vendors alike echoed a new reality: SOAR is no longer a luxury for overworked teams—it’s the foundation of modern security operations.

Across the show floor, we saw next-gen platforms powered by LLMs, low-code interfaces built for security analysts, and orchestration layers designed to integrate seamlessly across data, identity, and endpoint ecosystems. The goal was speed and precision. AI agents are now summarizing incidents, escalating only what matters, and stitching together context faster than most Tier 1 analysts ever could.

“The goal isn’t to eliminate analysts—it’s to amplify them. SOAR should act as your first responder, not just your alert router.”
— Mike Horn, SVP & GM, Splunk

The key shift? SOAR is evolving from a tool you configure… to a teammate you rely on.

Here’s what stood out from our demos, discussions, and deep dives with the teams reshaping incident response at RSA 2025.

LLMs Are Powering Context-Aware Workflows

Splunk’s new SOAR engine made waves with its integration of LLMs that can interpret logs, correlate across systems, and dynamically choose the next step—no static playbook required.

At their booth, we watched a simulated phishing alert go through Splunk SOAR, where the LLM analyzed email metadata, cross-referenced employee behavior patterns, and recommended a confidence-scored response—all in less than 60 seconds.

SimSpace showed how they train with realistic simulations of your production environment to preemptively reduce cyber risk by testing the readiness of people, process, and technology.

SOAR Evolves from Reactive to Predictive

Anomali introduced its integrated agentic AI technology, designed to supercharge threat detection, investigation, and response across its security platform.

SafeBreach showcased its updated QuickShell research and new product innovations, emphasizing continuous security validation through automated breach and attack simulations.

The release of Titanium X, a two-year labor for Open Text, promised enhanced productivity through automation, faster decision-making and scalable integration across hybrid and multi-cloud environments.

Arctic Wolf introduced Cipher, an AI security assistant built on its Aurora platform, and hosted a Threat Briefing Breakfast to discuss advancements in autonomous Security Operations Centers (SOCs).

Low-Code and No-Code Expand SOAR’s Reach

Swimlane introduced Autonomous Triage Agents, designed for use by Tier 1 analysts (or even business-side users) via a low-code interface. These agents are trained to take action on common incidents like privilege escalations, phishing attempts, or failed MFA authentications—no scripting required.

Tines brought a fresh angle by showcasing no-code workflows not just for SOC use cases, but also insider threat and fraud response—democratizing automation across the org.

What We Heard in the Hallways

“We’re not just drowning in alerts—we’re drowning in micro-decisions. Good tools help us skip straight to resolution.”
— Tom Gillis, SVP & GM, Cisco

“The future of SOAR is not pre-built—it’s responsive, iterative, and trained on your environment.”
— Ravi Kadiri, Senior Security Architect, AWS

Why It Matters

RSAC 2025 showed that SOAR isn’t just an operational tool anymore—it’s becoming the strategic automation layer for modern security programs.

The best platforms on display were:

  • Driven by real-time AI, not just decision trees
  • Built to autonomously handle high-frequency incidents
  • Equipped with tools to map and narrate cross-platform attack paths
  • Designed for low-code or no-code deployment across teams

If your SOAR still runs on rigid playbooks and rules, it’s time for a serious upgrade. Check out our vetted list of SOAR solution providers.

For more insights and detailed discussions from RSA Conference 2025, explore the full agenda and session recordings available on the RSA Conference website.

Related

Key players

Enter a search